Hack The Box Challenge — Factory
Factory exposes an unauthenticated Modbus RTU bridge, allowing PLC mode and valve coils to be manipulated by following the supplied ladder logic.
Read write-uproot@kali:~$ ls ./writeups/challenges
Focused, reproducible solutions for retired Hack The Box technical challenges.
Knowledge base
Each entry explains the weakness, reasoning, solver or exploit, validation and key learning outcome.
12 write-ups
Factory exposes an unauthenticated Modbus RTU bridge, allowing PLC mode and valve coils to be manipulated by following the supplied ladder logic.
Read write-upA custom Modbus/TCP service exposes PLC memory writes, allowing a stored MD5 password digest to be replaced and authentication bypassed safely.
Read write-upA Modbus/TCP packet capture hides an encoded message in register addresses, demonstrating how protocol metadata can become a covert data channel.
Read write-upOmniWatch chains Zig CRLF response splitting, Varnish cache poisoning, bot-targeted XSS, firmware LFI, JWT forgery and stacked SQL injection.
Read write-upSocratesPanel chains fat-GET cache poisoning, reflected XSS, an admin-only SSRF and Redis inline-command injection to recover a cached secret.
Read write-upPhantomFeed chains a ReDoS-amplified registration race, Nuxt open redirect and OAuth token theft with ReportLab RCE to recover the flag.
Read write-upAlien Complaint Form combines stored HTML injection with an unsafe same-origin JSONP callback to bypass CSP and expose a bot-only cookie.
Read write-upHTB Proxy chains a DNS-based SSRF filter bypass, HTTP request smuggling and shell command injection to expose a randomized flag file.
Read write-upNexus Void chains scoped SQLite injection with unsafe Json.NET type handling to instantiate a command-running setter and achieve root code execution.
Read write-upVolnaya Forums chains nginx CRLF response splitting, path-scoped session fixation and self-XSS to execute code in an authenticated admin browser.
Read write-upE.Tree turns unsafe XPath construction into a boolean oracle, allowing two XML secret fragments to be recovered character by character.
Read write-upPhonebook exposes an LDAP wildcard injection that bypasses authentication and creates a response oracle for recovering a password one character at a time.
Read write-upTry a broader search or clear one of the filters.